Sign your own binaries with go-tool-base, part 3: keyless CI signing with OIDC
Part 2 left you with a KMS key your release pipeline can sign through and a role (<name>-signer) that’s allowed to call kms:Sign and nothing else. There’s one obvious question left hanging: how does a CI job become that …







